Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 2a00:1450:4001:804::2013:80 · api.suaps.it
2026-02-14 15:26
HTTP/1.1 302 Found location: https://api.suaps.it/ x-cloud-trace-context: 569e895f852b51274455e975d8288256 date: Sat, 14 Feb 2026 15:26:51 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.186.147:443 · api.suaps.it
2026-01-22 22:26
HTTP/1.1 200 OK access-control-allow-origin: * content-type: text/html; charset=utf-8 etag: W/"48-qLVnjioL80EGvGQy3e+yRA64CwY" x-cloud-trace-context: e5c75f2bf44542aee71e2373146b0b13 date: Thu, 22 Jan 2026 22:26:40 GMT server: Google Frontend Content-Length: 72 Connection: close Merin-Univers API - Developped by Jonas Roussel & Edward Lindao Marazita
Open service 142.250.186.147:443 · api.suaps.it
2026-01-10 02:21
HTTP/1.1 200 OK access-control-allow-origin: * content-type: text/html; charset=utf-8 etag: W/"48-qLVnjioL80EGvGQy3e+yRA64CwY" x-cloud-trace-context: e400b3fb9d00288865c1db9fb78b5e5f date: Sat, 10 Jan 2026 02:21:20 GMT server: Google Frontend Content-Length: 72 Connection: close Merin-Univers API - Developped by Jonas Roussel & Edward Lindao Marazita